Skip to content

SECURITY: acct keyIds still bypass actor/public-key binding checks#327

Merged
pmusaraj merged 1 commit into
mainfrom
patch-1421-acct-keyids-still-bypass-actor-p-c2c52f
Jul 10, 2026
Merged

SECURITY: acct keyIds still bypass actor/public-key binding checks#327
pmusaraj merged 1 commit into
mainfrom
patch-1421-acct-keyids-still-bypass-actor-p-c2c52f

Conversation

@pmusaraj

Copy link
Copy Markdown
Contributor

Summary

Correctly validate acct: HTTP Signature keyIds by resolving them via WebFinger and enforcing actor-to-public-key binding checks. This prevents remote actors from being associated with unauthorized public keys during ActivityPub signature verification.

Source

Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com>

@pmusaraj
pmusaraj merged commit f99854b into main Jul 10, 2026
6 of 7 checks passed
@pmusaraj
pmusaraj deleted the patch-1421-acct-keyids-still-bypass-actor-p-c2c52f branch July 10, 2026 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants